Skip to content
Back to the Journal
Regional & Regulatory Perspectives

The Principle of Sufficiency: Why Coverage is the Only Metric that Matters in NIS2

In the world of NIS2 and critical infrastructure, "partial compliance" is a contradiction in terms. Explore the three layers of sufficiency required for a defensible audit.

Vivid Risk Editorial7 min read

The Danger of Incomplete Governance

In traditional IT auditing, “Sufficiency” was often determined by a small sample size. An auditor would pick 5 servers out of 500 and assume the rest were configured the same way. Under modern regulations like NIS2, this “Sample-Based Trust” is no longer sufficient. Digital dependency is total; therefore, governance must be total.

Defining “Sufficiency”

Sufficiency is not about how many pages your policy manual has. It is the measure of the Defensibility Gap between your stated intent and your technical reality across 100% of your critical assets.

The Three Layers of Sufficiency

1. Control Sufficiency (The Breadth)

Are you covering all ten chapters of the NIS2 Article 21? Most organisations focus heavily on “Access Control” while leaving “Supply Chain Security” or “Cyber Hygiene” as abstract concepts. Sufficiency requires a uniform density of governance across all required domains.

2. Evidence Sufficiency (The Depth)

A single PDF of a backup configuration from six months ago is not sufficient. Sufficiency requires “Temporal Density”—proof that the control is functioning continuously. This is why Vivid Risk prioritises metadata-driven evidence over manual uploads.

3. Asset Sufficiency (The Coverage)

This is the most common point of failure. If your Asset Registry only captures 70% of your cloud environment, your governance is 0% sufficient for the remaining 30%. True sufficiency requires a dynamic link where new infrastructure is automatically “born” with governance obligations.

Closing the Sufficiency Gap

The role of Vivid Risk is to act as a Sufficiency Engine. We don’t just tell you what is “Done”; we expose the “Governance Shadows”—the assets that aren’t monitored, the controls that lack recent evidence, and the services that are failing their SLAs.

Conclusion

Sufficiency is the difference between a performative audit and a resilient business. When you can prove that 100% of your critical assets meet 100% of your regulatory obligations 100% of the time, you haven’t just achieved compliance—you’ve achieved structural security.